QID 997235

Date Published: 2024-02-15

QID 997235: PHP (Composer) Security Update for typo3/cms-core (GHSA-rj3x-wvc6-5j66)

Entities of the File Abstraction Layer (FAL) could be persisted directly via DataHandler. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compatibility layer for files located outside properly configured file storages and within the public web root directory. Exploiting this vulnerability requires a valid backend user account.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-rj3x-wvc6-5j66 for updates and patch information.
    Vendor References

    CVEs related to QID 997235

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rj3x-wvc6-5j66 typo3/cms-core URL Logo github.com/advisories/GHSA-rj3x-wvc6-5j66